Impact
An unauthenticated attacker on the same local network can control another Nx server's site name field and inject JavaScript. When an authenticated administrator opens the "Merge with Another Site" dialog in the Web Administration interface, the malicious script executes in the administrator's browser, exfiltrating the session cookie. This permits takeover of the administrator account, effectively providing remote code execution within the browser context. The flaw is a stored cross‑site scripting vulnerability (CWE‑79).
Affected Systems
Network Optix Nx Witness VMS, versions prior to 6.1.3, on Linux, Windows, and macOS operating systems are vulnerable. The issue affects only the Web Administration interface accessed over HTTP/HTTPS and requires the administrator be logged in to use the web UI.
Risk and Exploitability
With a CVSS score of 8 the vulnerability is considered high severity. The EPSS metric is not available; it is not listed in CISA KEV, indicating no publicly reported exploits at the time of analysis. Exploitation requires an adjacent Nx server that an attacker can control and a logged‑in administrator who opens the merge dialog, so practical risk depends on network topology and user interaction. The high score and ability to steal session tokens make it a serious threat for organizations with lax network segmentation.
OpenCVE Enrichment